Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows authenticated users to allow arbitrary HTML code to be reflected in the response web page via crafted user input of attributes.
References
Configurations
History
21 Nov 2024, 03:26
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 3.5
v3 : 3.5 |
References | () https://kc.mcafee.com/corporate/index?page=content&id=SB10192 - |
07 Nov 2023, 02:44
Type | Values Removed | Values Added |
---|---|---|
References | () https://kc.mcafee.com/corporate/index?page=content&id=SB10192 - |
Information
Published : 2018-05-25 13:29
Updated : 2024-11-21 03:26
NVD link : CVE-2017-3961
Mitre link : CVE-2017-3961
CVE.ORG link : CVE-2017-3961
JSON object : View
Products Affected
mcafee
- network_security_manager
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')